State Street Corporation

SIEM Data Engineer

State Street Corporation$90K — $157K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in SIEM engineering or security data engineering, with hands-on experience using Splunk or similar platforms.
  • 2+ years of experience with Cribl Stream or comparable data pipeline technologies.
  • 2+ years of experience with Databricks or large-scale data platforms for analytics.
  • Strong understanding of logging mechanisms from various enterprise environments, including cloud and endpoint.
  • Familiarity with data quality concepts and validation techniques.

Responsibilities

  • Support onboarding of security telemetry from diverse enterprise sources.
  • Analyze source log formats to define ingestion and routing requirements.
  • Configure telemetry pipelines for data processing and routing.
  • Ensure delivery of security telemetry into data platforms like Databricks.
  • Validate data quality for accuracy, completeness, and schema consistency.
  • Troubleshoot data flow issues across multiple systems and platforms.
  • Document data onboarding patterns and operational procedures.

Benefits

  • 401K retirement savings plan with company match.
  • Insurance coverage including life, medical, dental, and vision.
  • Paid time off for vacation, sick leave, and family care.
  • Access to Employee Assistance Program for wellness support.
  • Eligibility for performance-based annual incentive compensation.
Full Job Description

Who we are looking for

We are looking for aSIEM Data Engineerreporting directly to theCyber Data Engineering Manager. You will support the onboarding, transformation, routing, validation, and operational support of cybersecurity telemetry and enterprise log data used for security monitoring, analytics, reporting, incident response, and cyber data science use cases.

This role is focused on understanding diverse enterprise data sources,buildingandmaintainingsecurity telemetry pipelines, validating data quality, and ensuring reliable delivery of high-quality data into cyber data platforms such as Splunk, Databricks, and other SIEM or cyber analytics platforms. You will work closely with cybersecurity, infrastructure, cloud, application, anddata engineering teams to ensure security telemetry isaccurate, searchable, complete, and fit for purpose.

Why ThisRole Is Important to Us

The team you will be joining is part ofCyber Data & Analytics, a function that is vital to the company as it enables cybersecurity teams to make faster, data-driven decisions and strengthen the firm27s ability to detect, investigate, and respond to evolving cyber threats.

High-quality cybersecurity data is foundational to effective threat detection, incident response, risk reporting, observability, automation, analytics, and compliance. This role helps ensure that enterprise security telemetry is properly onboarded,validated, enriched, routed,monitored, and continuously available to support critical cyber defense capabilities.

What you willbe responsible for

AsSIEM Data Engineeryou will:

  • Support onboarding of security telemetry from applications, infrastructure, endpoints, identity platforms, network devices, cloud services, SaaS tools, databases, and security products.

  • Analyze source log formats and define ingestion requirements, expected fields, metadata, routing needs, and downstream SIEM/analytics use cases.

  • Configure telemetry pipelines for parsing, filtering, masking, enrichment, normalization, event breaking, metadata tagging, and destination routing.

  • Route security telemetry toSplunk, Databricks, and other SIEM or cyber analytics platforms.

  • Support validation and delivery of security telemetry into Databricks across raw, enriched, and curated data layers.

  • Support ingestion patterns such as syslog, HEC, REST APIs, cloud storage, streaming services, forwarders, and agent-based integrations.

  • Validate data quality in Splunk and Databricks for freshness, completeness, timestamp accuracy, field availability, schema consistency, source attribution, and routing accuracy.

  • Troubleshoot ingestion and data flow issues across sources, collectors, pipelines, SIEM platforms, Databricks tables, APIs, cloud storage, and streaming platforms.

  • Providesecond-line-of-defense supportfor operational issues related to data engineering jobs, pipelines, ingestion failures, and issues leading to loss of data delivery to cyber data platforms.

  • Collaborate with Detection Engineering, Security Operations, Cyber Data Science, Observability, Cloud, Infrastructure, Application, and Platform teams to ensure telemetry supports security use cases.

  • Assistwith source type assignment, index routing, taxonomy tagging, metadata enrichment, CIM alignment, schema mapping, and data validation.

  • Monitor pipeline health, dropped events, destination failures, ingestion latency, queue growth, and data delivery issues.

  • Document onboarding patterns, field mappings, transformation logic, routing decisions, data flow diagrams, runbooks, troubleshooting procedures, and operational handoffs.

  • Participate in production support, change management, incident response, root cause analysis, and continuous improvement activities

  • Second-line-of-defense support for operational issues related to data engineering (jobs/pipelines) and issues leading to loss of data delivery to Cyber data platforms

What we value

These skills will help you succeed in this role

  • Strong understanding of SIEM data onboarding, log ingestion, data routing, parsing, enrichment, validation, and troubleshooting.

  • Hands-on experience withSplunkor similar SIEM/log analytics platforms.

  • Hands-on experience or working knowledge ofCribl Streamor similar data pipeline technologies for routing, filtering, parsing, enrichment, transformation, and destination delivery.

  • Ability to understand and onboard telemetry from diverse enterprise data sources across cloud, endpoint, identity, network, application, infrastructure, database, SaaS, and security platforms.

  • Familiarity with common log formats such asJSON, XML, CSV, key-value, syslog, Windows Event Logs, cloud audit logs, API responses, and application logs.

  • Working knowledge of Databricks or similar analytics/lakehouseplatforms is preferred.

  • Familiarity with Databricks data layers and data engineering concepts, including raw data ingestion, enrichment, curated tables, SQL-based validation, and analytics-ready datasets.

  • Ability to useSPL, SQL, Spark SQL, Python, Shell, or PowerShellfor data validation, querying, troubleshooting, and automation.

  • Understandingdata quality concepts, including log fidelity, event completeness, timestamp accuracy, field consistency, duplicate detection, routing validation, and data delivery monitoring.

  • Strong documentation, communication, collaboration, prioritization, and problem-solving skills.



Education & Preferred Qualifications

  • Master27s or bachelor27sdegree in computer science, Cybersecurity, Information Technology, Engineering, Data Engineering, Data Analytics, Information Systems, or a related technical field; equivalent work experience may also be considered

  • 5+ years of experience in SIEM engineering, security data engineering, cybersecurity platform operations, or log analytics, with hands-on experience using Splunk or similar SIEM/log analytics platforms.

  • 2+ years of experience with Cribl Stream or similar data pipeline technologies such as Fluent Bit/Fluentd, Vector, Kafka,Syslog, HEC, REST APIs, or cloud-native ingestion services.

  • 2+ years of experiencewithDatabricks, datalakehouseplatforms, large-scale analytics platforms, or security data repositories for telemetry validation, analytics, and data engineering use cases.

  • Experience onboarding,validating, and troubleshooting security telemetry from diverse enterprise sources to support threat detection, observability, incident response, reporting, and cyber analytics use cases.

  • Experience querying and validating data usingSPL, SQL, Spark SQL, Python, or similar languages.

  • Experience analyzing logs from cloud, endpoint, network, identity, infrastructure, application, database, SaaS, and security tools.

  • Experience with production support, issue troubleshooting, ticket documentation, root cause analysis, operational handoffs, and continuous service improvement.

  • Relevant certifications are preferred, includingCribl certificationssuch asCribl Certified Observability Engineer,Splunk certificationssuch asSplunk Certified Admin,Splunk Certified Architect, orSplunk Certified Consultant, or equivalent hands-on platform experience.

  • Cloud, infrastructure, data engineering, or cybersecurity certifications are a plus.

WorkRequirement

  • This role may follow ahybrid work model, with in-office presencerequiredbased on team, business, and location expectations.

  • Standard working hours are 8:00 AM to 5:00 PM local time for the employee27s designated work location. Flexibility may berequiredfor occasional operational support, release of activities, incident resolution, escalation support, or datadelivery ofrecovery efforts.

Salary Range:

$90,000 - $157,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street27s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit .

About State Street Corporation

State Street Corporation Careers

Join the dynamic team at State Street Corporation, a leading financial services provider known for its commitment to innovation, leadership, and professional growth. As a global powerhouse in investment management and servicing, we offer unparalleled job opportunities that propel your career to new heights.

Work You’ll Do

At State Street Corporation, you’ll be part of a culture that values diversity, leadership, and continuous professional development. Engage in work that transforms the financial landscape and helps our clients achieve their investment goals. Our team at State Street is at the forefront of combining industry expertise with cutting-edge technology to deliver exceptional service and results.

Explore Our Job Opportunities

Whether you’re looking for an entry-level position or a senior role, State Street Corporation offers a range of career paths in areas such as asset management, data analytics, finance, and technology. Our hiring process is designed to identify and nurture talent, focusing on your skills and potential. Prepare your resume, ace the interview, and join a team that’s committed to your career growth.

Internship Programs

Kickstart your career with a State Street internship. Our programs provide hands-on experience, networking opportunities, and professional mentoring in a real-world setting. Interns at State Street gain valuable insights and skills that make them competitive candidates for full-time positions within our company.

Benefits and Growth

State Street Corporation is dedicated to the growth and well-being of our employees. We offer a comprehensive benefits package that supports both your professional and personal life. From advanced career training and leadership development programs to health and wellness benefits, we ensure that our team members have the resources they need to succeed.

Inclusive Culture and Diversity

We pride ourselves on fostering an inclusive environment where every employee can thrive. Diversity is not just embraced; it’s celebrated. At State Street, you’ll work alongside a diverse group of professionals who bring a wide range of perspectives and ideas to the table. Our diversity training programs are designed to enhance collaboration and innovation across our global team.

Stay Connected

Join Our Team Discover the career you’ve always wanted by exploring the job opportunities at State Street Corporation. We look for driven, curious, and innovative team players who are ready to make an impact. Search State Street jobs now and find the position that best matches your skills and interests. Keep Up to Date Stay informed with career tips, insider perspectives, and industry-leading insights you can use today—all from the people who work here. Our careers blog provides you with the latest trends, tools, and advice to keep you ahead in your professional journey.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at State Street Corporation, where your career development is our priority. Join State Street Corporation and be part of a team that values innovation, leadership, and a commitment to excellence. Your future in the financial services industry starts here.
Learn more about State Street Corporation
Size
39,335 employees
Market Cap
$28.4 billion
Industry
Net Income
$2.4 billion
Founded
1792
5 Year Trend
-4.9%
NASDAQ

Similar Jobs

More Jobs at State Street Corporation

More Information Technology Jobs

Find similar SIEM Data Engineer jobs: